Vulnerability Detection for software-intensive system

被引:0
|
作者
Othman, Refat [1 ]
机构
[1] Free Univ Bozen Bolzano, Bolzano, Bolzano, Italy
关键词
ATT&CK; CAPEC; CWE; CVE; Transformer models; Pretrained language models;
D O I
10.1145/3661167.3661170
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Cyberattacks are becoming more sophisticated, and organizations are constantly under threat from various types of security breaches. To protect against these threats, it is essential to identify the vulnerability and impact of these weaknesses and address them before attackers can exploit them. However, manually identifying and characterizing vulnerability can be a time-consuming and tedious process that adds to the workload of cybersecurity experts. To address this challenge, this research plan presents a doctoral research proposal to automate the process of identifying novel technologies, including learning-based technologies, to infer vulnerabilities from a text about an attack. In addition, this research plan uses natural language processing techniques to extract relevant information from attack text and analyze repositories for known vulnerabilities. This research plan presents an in-depth analysis of the research challenges and goals to understand how innovative technologies can be used to detect and identify vulnerabilities in text about attacks. It also covers the preliminary work done, literature review findings, and threats to validity.
引用
收藏
页码:510 / 515
页数:6
相关论文
共 50 条
  • [41] Comparing the Effectiveness of SFMEA and STPA in Software-Intensive Railway Level Crossing System
    Tung La-Ngoc
    Kwon, Gihwon
    ADVANCES IN COMPUTER SCIENCE AND UBIQUITOUS COMPUTING, 2018, 474 : 1281 - 1288
  • [42] The domain analysis and design of system-testing equipment for software-intensive avionics
    Zhong, Deming
    Liu, Bin
    Ruan, Lian
    Wang, Yichen
    2006 IEEE AUTOTESTCON, VOLS 1 AND 2, 2006, : 502 - 508
  • [43] An empirical development case of a software-intensive system based on the rational unified process
    Lee, Kilsup
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 5, 2006, 3984 : 877 - 886
  • [44] Timely and Accurate Detection of Model Deviation in Self-Adaptive Software-Intensive Systems
    Tong, Yanxiang
    Qin, Yi
    Jiang, Yanyan
    Xu, Chang
    Cao, Chun
    Ma, Xiaoxing
    PROCEEDINGS OF THE 29TH ACM JOINT MEETING ON EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING (ESEC/FSE '21), 2021, : 168 - 180
  • [45] Reliability-related requirements in software-intensive systems
    Hecht, Myron
    Owens, Karen
    Tagami, Joanne
    ANNUAL RELIABILITY AND MAINTAINABILITY SYMPOSIUM, 2007 PROCEEDINGS, 2006, : 155 - +
  • [46] Ontology Learning and its Application in Software-Intensive Projects
    Guo, Jin
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING COMPANION (ICSE-C), 2016, : 843 - 846
  • [47] A HOLISTIC VIEW AT DEPENDABLE EMBEDDED SOFTWARE-INTENSIVE SYSTEMS
    Schoitsch, Erwin
    IDIMT-2008: MANAGING THE UNMANAGEABLE, 2008, 25 : 321 - 344
  • [48] Programmable Managing of Workflows in Development of Software-Intensive Systems
    Sosnin, P.
    Lapshov, Y.
    Svyatov, K.
    MODERN ADVANCES IN APPLIED INTELLIGENCE, IEA/AIE 2014, PT I, 2014, 8481 : 138 - 147
  • [49] Substantially Evolutionary Theorizing in Designing Software-Intensive Systems
    Sosnin, Petr
    INFORMATION, 2018, 9 (04)
  • [50] A Security Metrics Taxonomization Model for Software-Intensive Systems
    Savola, Reijo M.
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2009, 5 (04): : 197 - 206